SAP security note 2132282, “Potential denial of service in BC-BMT-WFM-WEB”, is a program error note released on 24.08.2017. Below are the symptom, SAP recommended solution and the affected software components.
Description
Symptom
An attacker can remotely exploit BC-BMT-WFM-WEB, rendering it, and potentially the resources that are used to serve BC-BMT-WFM-WEB, unavailable.
Solution
Implement the correction instructions.
The XML deserialization is protected by an additional function, which uses heuristics to mitigate any attacks. Under certain circumstances, the heuristics might be triggered even though there is no attack (false positive). As a result, you can deactivate this function in transaction SWPA (see attachment “parameter.docx”).
Reason and prerequisites
An attacker can cause a situation in which the process enters an endless loop that claims the entire available processing time. This causes the entire system to become unresponsive until the process is terminated manually. An attacker can use this flaw to launch a denial-of-service (DoS) attack.
References
This note refers to
Affected components
- SAP_BASIS 700 to 702
- SAP_BASIS 710 to 711
- SAP_BASIS 730
- SAP_BASIS 731
- SAP_BASIS 740
Full note on SAP: SAP Support Launchpad note 2132282
Detailed exploitation and proof-of-concept material for this note is maintained in the RedRays Security Platform. For access, contact [email protected].
